CVE-2026-12724 PUBLISHED

Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password

Assigner: WPScan
Reserved: 19.06.2026 Published: 20.07.2026 Updated: 20.07.2026

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.

Product Status

Vendor Unknown
Product Kirki
Versions Default: unaffected
  • affected from 0 to 6.0.12 (excl.)

Credits

  • Tarcísio Luchesi finder
  • WPScan coordinator

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE